
Dutch VPS and Borrowed ISP Relays Power Ranapama Infostealer C2
A single LeaseWeb VPS in the Netherlands anchors a 57-IP command-and-control network for the ranapama infostealer, with the operator hiding behind compromised Korean broadband endpoints, Belarusian mobile subscriber lines, and a factory-default TP-Link router on the Palestinian PALTEL network. The architecture is designed to make attribution and takedown significantly harder than a conventional dedicated-hosting C2 cluster. CTX Team first observed the campaign on 10 June 2026.
A Let's Encrypt certificate minted on 29 January 2026 for the domain aceinco.com — valid for exactly 89 days, hosted on a LeaseWeb Netherlands VPS at 85.17.31.111 (AS60781) — is the clearest fingerprint of operator-controlled infrastructure in a 57-IP command-and-control network assembled around the ranapama infostealer. Everything else in the observable pool appears to be borrowed: compromised Korea Telecom broadband endpoints, hijacked subscriber lines on a Belarusian mobile carrier, and at…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read